The Experts below are selected from a list of 101619 Experts worldwide ranked by ideXlab platform
Gursun Gonca - One of the best experts on this subject based on the ideXlab platform.
-
Routing-Aware Partitioning of the Internet Address Space for Server Ranking in CDNs
'Elsevier BV', 2018Co-Authors: Gursun GoncaAbstract:The goal of Content Delivery Networks (CDNs) is to serve content to end-users with high performance. In order to do that, a CDN measures the latency on the paths from its servers to users and then selects a best available server for each user. For large CDNs, monitoring paths from thousands of servers to millions of users is a challenging task due to its size. In this paper, we Address this problem and propose a framework to scale the task of path monitoring. Simply stated, the goal of our framework is clustering IP Addresses (clients) such that in each cluster the choice of best available server is same (or similar). Then, finding a best available server for one client in a given cluster will be sufficient to assign that server to the rest of the clients in the cluster. To achieve this goal, first we introduce two distance metrics to compute how similar the server choices of any given two clients. Second, we use a clustering method that is based on interdomain routing information. We evaluate the goodness of our clusters by using the metrics we introduce. We show that there is a strong correlation between the similarity in how two destination clients are routed to in the Internet and the similarity in their server selections. Finally, we show how to choose representative clients from each cluster so that it is sufficient to learn the latencies from the CDN servers to the representative and find a best available server accordingly for the rest of the clients in the same cluster.Comment: A more recent version of this manuscript is published in Elsevier Computer Communications, July 2017. Please cite accordingl
-
Routing-aware partitioning of the Internet Address space for server ranking in CDNs
'Elsevier BV', 2017Co-Authors: Gursun GoncaAbstract:The goal of Content Delivery Networks (CDNs) is to serve content to end-users with high performance. In order to do that, a CDN measures the latency on the paths from its servers to users and then selects a best available server for each user. For large CDNs, monitoring paths from thousands of servers to millions of users is a challenging task due to its size. In this paper, we Address this problem and propose a framework to scale the task of path monitoring. Simply stated, the goal of our framework is clustering IP Addresses (clients) such that in each cluster the choice of best available server is same (or similar). Then, finding a best available server for one client in a given cluster will be sufficient to assign that server to the rest of the clients in the cluster. To achieve this goal, first we introduce two distance metrics to compute how similar the server choices of any given two clients. Second, we use a clustering method that is based on interdomain routing information. We evaluate the goodness of our clusters by using the metrics we introduce. We show that there is a strong correlation between the similarity in how two destination clients are routed to in the Internet and the similarity in their server selections. Finally, we show how to choose representative clients from each cluster so that it is sufficient to learn the latencies from the CDN servers to the representative and find a best available server accordingly for the rest of the clients in the same cluster
Selvakumar Manickam - One of the best experts on this subject based on the ideXlab platform.
-
a study on detecting icmpv6 flooding attack based on ids
2013Co-Authors: Redhwan M A Saad, Sureswaran Ramadass, Selvakumar ManickamAbstract:The rapid growth of the Internet usage has caused problem on Internet Address space. IPv6 was designed to Address the problem of the adoption of IPv4 Addresses by introducing a large number of Address spaces. Currently, a lot of networking devices consider as IPv6 that are bled supporting including routers, notebooks, PCs, and hand phone. The devices deployed dual stack IPv4/IPv6 mechanism as a step toward the full implementation of IPv6 in the future. Today the network security is becoming increasingly a significant issue. In order to exploit the networks and get all the benefits of IPv6, networks require to be secured in an effective and efficient manner. Security products such as Network Intrusion Detection Systems have less support for the IPv6 protocols than for their IPv4 counterparts either in terms of performance or in terms of features. One of significant protocol in IPv6 implementation that is utilized on neighbor and router discovery is ICMPv6. Nevertheless, this protocol also could be used by attacker to deny network services such as ICMPv6 flood attacks that makes network performance decreases. This paper presents a reviewing related on ICMPv6 security considerations and methods of detect ICMPv6 flooding attacks.
-
A Study on Detecting ICMPv6 Flooding Attack based
2013Co-Authors: Redhwan M A Saad, Sureswaran Ramadass, Selvakumar ManickamAbstract:Abstract: The rapid growth of the Internet usage has caused problem on Internet Address space. IPv6 was designed to Address the problem of the adoption of IPv4 Addresses by introducing a large number of Address spaces. Currently, a lot of networking devices consider as IPv6 that are bled supporting including routers, notebooks, PCs, and hand phone. The devices deployed dual stack IPv4/IPv6 mechanism as a step toward the full implementation of IPv6 in the future. Today the network security is becoming increasingly a significant issue. In order to exploit the networks and get all the benefits of IPv6, networks require to be secured in an effective and efficient manner. Security products such as Network Intrusion Detection Systems have less support for the IPv6 protocols than for their IPv4 counterparts either in terms of performance or in terms of features. One of significant protocol in IPv6 implementation that is utilized on neighbor and router discovery is ICMPv6. Nevertheless, this protocol also could be used by attacker to deny network services such as ICMPv6 flood attacks that makes network performance decreases. This paper presents a reviewing related on ICMPv6 security considerations and methods of detect ICMPv6 flooding attacks
Olaf Maennel - One of the best experts on this subject based on the ideXlab platform.
-
evolution of Internet Address space deaggregation myths and reality
IEEE Journal on Selected Areas in Communications, 2010Co-Authors: Luca Cittadini, W Muhlbauer, Steve Uhlig, Randy Bush, Pierre Francois, Olaf MaennelAbstract:Internet routing table size growth and BGP update churn are two prominent Internet scaling issues. There is widespread belief in a high and fast growing number of ASs that deaggregate prefixes, e.g., due to multi-homing and for the purpose of traffic engineering. Moreover, researchers often blame specific classes of ASs for generating a disproportionate amount of BGP updates. Our primary objective is to challenge such widespread assumptions (“myths”) and not solely to confirm previous findings. Surprisingly, we find severe discrepancies between existing myths and reality. According to our results, there is no trend towards more aggressive prefix deaggregation or traffic engineering over time. With respect to update dynamics, we observe that deaggregated prefixes generally do not generate a disproportionate number of BGP updates, with respect to their share of the BGP routing table. On the other side, we observe much more widespread traffic engineering in the form of AS path prepending and scoped advertisements compared to previous studies. Overall, our work gives a far more positive picture compared to the alarming discourses typically heard: The impact of “bad guys” on routing table size growth and BGP churn has not changed for the worse in recent years. Rather, it increases at the same pace as the Internet itself.
Redhwan M A Saad - One of the best experts on this subject based on the ideXlab platform.
-
a study on detecting icmpv6 flooding attack based on ids
2013Co-Authors: Redhwan M A Saad, Sureswaran Ramadass, Selvakumar ManickamAbstract:The rapid growth of the Internet usage has caused problem on Internet Address space. IPv6 was designed to Address the problem of the adoption of IPv4 Addresses by introducing a large number of Address spaces. Currently, a lot of networking devices consider as IPv6 that are bled supporting including routers, notebooks, PCs, and hand phone. The devices deployed dual stack IPv4/IPv6 mechanism as a step toward the full implementation of IPv6 in the future. Today the network security is becoming increasingly a significant issue. In order to exploit the networks and get all the benefits of IPv6, networks require to be secured in an effective and efficient manner. Security products such as Network Intrusion Detection Systems have less support for the IPv6 protocols than for their IPv4 counterparts either in terms of performance or in terms of features. One of significant protocol in IPv6 implementation that is utilized on neighbor and router discovery is ICMPv6. Nevertheless, this protocol also could be used by attacker to deny network services such as ICMPv6 flood attacks that makes network performance decreases. This paper presents a reviewing related on ICMPv6 security considerations and methods of detect ICMPv6 flooding attacks.
-
A Study on Detecting ICMPv6 Flooding Attack based
2013Co-Authors: Redhwan M A Saad, Sureswaran Ramadass, Selvakumar ManickamAbstract:Abstract: The rapid growth of the Internet usage has caused problem on Internet Address space. IPv6 was designed to Address the problem of the adoption of IPv4 Addresses by introducing a large number of Address spaces. Currently, a lot of networking devices consider as IPv6 that are bled supporting including routers, notebooks, PCs, and hand phone. The devices deployed dual stack IPv4/IPv6 mechanism as a step toward the full implementation of IPv6 in the future. Today the network security is becoming increasingly a significant issue. In order to exploit the networks and get all the benefits of IPv6, networks require to be secured in an effective and efficient manner. Security products such as Network Intrusion Detection Systems have less support for the IPv6 protocols than for their IPv4 counterparts either in terms of performance or in terms of features. One of significant protocol in IPv6 implementation that is utilized on neighbor and router discovery is ICMPv6. Nevertheless, this protocol also could be used by attacker to deny network services such as ICMPv6 flood attacks that makes network performance decreases. This paper presents a reviewing related on ICMPv6 security considerations and methods of detect ICMPv6 flooding attacks
Luca Cittadini - One of the best experts on this subject based on the ideXlab platform.
-
evolution of Internet Address space deaggregation myths and reality
IEEE Journal on Selected Areas in Communications, 2010Co-Authors: Luca Cittadini, W Muhlbauer, Steve Uhlig, Randy Bush, Pierre Francois, Olaf MaennelAbstract:Internet routing table size growth and BGP update churn are two prominent Internet scaling issues. There is widespread belief in a high and fast growing number of ASs that deaggregate prefixes, e.g., due to multi-homing and for the purpose of traffic engineering. Moreover, researchers often blame specific classes of ASs for generating a disproportionate amount of BGP updates. Our primary objective is to challenge such widespread assumptions (“myths”) and not solely to confirm previous findings. Surprisingly, we find severe discrepancies between existing myths and reality. According to our results, there is no trend towards more aggressive prefix deaggregation or traffic engineering over time. With respect to update dynamics, we observe that deaggregated prefixes generally do not generate a disproportionate number of BGP updates, with respect to their share of the BGP routing table. On the other side, we observe much more widespread traffic engineering in the form of AS path prepending and scoped advertisements compared to previous studies. Overall, our work gives a far more positive picture compared to the alarming discourses typically heard: The impact of “bad guys” on routing table size growth and BGP churn has not changed for the worse in recent years. Rather, it increases at the same pace as the Internet itself.